// POSTS TAGGED "incident-response"
Incident Response.
All posts tagged incident-response.
← back to all postsThe Slow Call Is Still the Job
Security leadership rewards speed. The calls I am proudest of during an active incident were the ones I forced myself to slow down on. That is a trained discipline, not a personality trait, and most playbooks never write it down.
When Your Vendor Gets Breached, You Find Out Last
A fintech software vendor got hit with ransomware and up to 1.35 million banking customers were exposed. Most of their banks did the questionnaire, got the SOC 2, and still found out months late. The control that matters isn't the one you audited.
Your Incident Response Plan Is Modeling the Wrong Threat Actor
LockBit dominated tabletops for years. The ransomware ecosystem has rotated. The groups hitting organizations right now are not the ones your IR team practiced against, and that gap has consequences.

Your Ransomware Negotiator Might Be Playing Both Sides
The DigitalMint conviction proves your IR vendor pre-vetting is part of your security program, not an afterthought. Here is what to ask before the next incident, not during it.

Your Tabletop Exercise Isn't Testing What You Think It Is
Most tabletop exercises are scripted theater that confirm what people already believe. Here's what actually breaks during a real incident, and how to design an exercise that finds it before someone else does.

Why Your Incident Response Plan Will Fail (And What to Build Instead)
Most IR plans fail not because they're poorly written, but because plans don't survive contact with reality. Here's how to build response capability instead of just documentation.

Feats of Endurance and Stupidity: What Running in Circles Teaches Us About Cybersecurity
What ultramarathon running teaches us about incident response and cybersecurity resilience. Lessons from a CISO on training for chaos, mental endurance, and why preparation beats reaction.

From Jewels to Data: Why We Never Learn
The Louvre got robbed. Companies get breached. Both could've been prevented. Here's why waiting for the 'oh crap' moment is a terrible security strategy.

When Perfect Plans Meet Imperfect Reality
Sometimes the consequences of IR plan failure aren't just about downtime or data. Sometimes they're about life and death.

The Question That Made Everyone in the Room Go Silent
I asked one simple question about incident response plans. The silence that followed told me everything I needed to know.